First published: Wed Jan 19 2022(Updated: )
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21252 is a vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples), which allows an unauthenticated attacker to compromise the server.
Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 are affected by CVE-2022-21252.
CVE-2022-21252 has a severity level of 6.5 (Medium).
An attacker can exploit CVE-2022-21252 by sending specially crafted HTTP requests to the vulnerable Oracle WebLogic Server.
No, CVE-2022-21252 can be exploited by an unauthenticated attacker with network access via HTTP.